CVE Explorer
CVE-2026-47241
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a raw string argument which is only validated to prevent CRLF injection and then sent verbatim. If this string is derived from user-controlled input, an attacker can force the next command to be absorbed as a continuation of the first command. This will cause the first command to eventually fail, but also prevents it from returning until another
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-162","description":"CWE-162: Improper Neutralization of Trailing Special Elements","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bba75662dc9346610a6fb6956866a1d68b55d166ae507a7e666916b49686b7f8 · sha256:57010adab85784fb… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-182","description":"CWE-182: Collapse of Data into Unsafe Value","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bba75662dc9346610a6fb6956866a1d68b55d166ae507a7e666916b49686b7f8 · sha256:57010adab85784fb… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-186","description":"CWE-186: Overly Restrictive Regular Expression","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bba75662dc9346610a6fb6956866a1d68b55d166ae507a7e666916b49686b7f8 · sha256:57010adab85784fb… · /containers/cna/problemTypes/2/descriptions/0
Affected products and versions
1 source assertion{"product":"net-imap","vendor":"ruby","versions":[{"status":"affected","version":">= 0.6.0, < 0.6.4.1"},{"status":"affected","version":"< 0.5.15"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:bba75662dc9346610a6fb6956866a1d68b55d166ae507a7e666916b49686b7f8 · sha256:57010adab85784fb… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":2.1,"baseSeverity":"LOW","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:bba75662dc9346610a6fb6956866a1d68b55d166ae507a7e666916b49686b7f8 · sha256:57010adab85784fb… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
3 source assertions{"cweId":"CWE-162","description":"CWE-162: Improper Neutralization of Trailing Special Elements","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bba75662dc9346610a6fb6956866a1d68b55d166ae507a7e666916b49686b7f8 · sha256:57010adab85784fb… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-182","description":"CWE-182: Collapse of Data into Unsafe Value","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bba75662dc9346610a6fb6956866a1d68b55d166ae507a7e666916b49686b7f8 · sha256:57010adab85784fb… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-186","description":"CWE-186: Overly Restrictive Regular Expression","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bba75662dc9346610a6fb6956866a1d68b55d166ae507a7e666916b49686b7f8 · sha256:57010adab85784fb… · /containers/cna/problemTypes/2/descriptions/0
Source references
1 source assertion{"name":"https://github.com/ruby/net-imap/security/advisories/GHSA-c4fp-cxrr-mj66","tags":["x_refsource_CONFIRM"],"url":"https://github.com/ruby/net-imap/security/advisories/GHSA-c4fp-cxrr-mj66"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bba75662dc9346610a6fb6956866a1d68b55d166ae507a7e666916b49686b7f8 · sha256:57010adab85784fb… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.